PT-2019-9656 · Columbia Weather · Columbia Weather Microserver

John Elder

+1

·

Publicado

2019-06-18

·

Atualizado

2019-06-18

·

CVE-2018-18877

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Columbia Weather MicroServer version MS 2.6.9900
Description The issue allows an authenticated web user to access an alternative configuration page, specifically the config main.php page, which enables manipulation of the device.
Recommendations For version MS 2.6.9900, restrict access to the config main.php page to prevent unauthorized device manipulation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18877

Produtos afetados

Columbia Weather Microserver